← LFCA: IT and operational foundations
05 / 7 · 35 MIN

Security, identities, and data

Limit access and manage secrets and data throughout their lifecycle.

Concept and mechanism

Authentication confirms control of an identity or authenticator; authorization defines permitted operations. MFA requires distinct factor types: a password and another memorized PIN remain knowledge factors. For automation, grant only necessary actions and resources and verify what should be denied. A shared administrative identity hinders attribution and broadens impact. Access review should follow role changes and team departure, covering applicable credentials, keys, and sessions. Do not assume disabling one local mechanism removes cloud access. Evidence must correspond to the system actually accepting the credential.

Guided application

In a fictional incident, a password was committed and shared. Gitignore handles untracked files rather than deleting old commits; it also does not revoke the destination password. Rotate or revoke the credential, update authorized consumers, and address copies and history through the incident process. Removing a local file does not demonstrate complete containment. Logs need similar care: collect sufficient diagnostic information without copying passwords, tokens, or unnecessary personal data. Limit reading, transport, retention, and sharing according to context. These are engineering practices; specific compliance requirements should be confirmed with appropriate owners. The course neither assumes an internal banking rule nor replaces that validation.

IN PRACTICE

Password removed from a file but still valid: exposure can remain useful to someone who obtained it.

Common pitfalls

Two steps as MFA; reader name as limited privilege; gitignore as revocation; compression as encryption.

Related topics: Linux, shell, and permissions · Services, logs, and capacity · Networking and recovery

Take this idea with you

Control validity, scope, and copies as well as the secret’s visible location.

Create account

Reference: Digital identity authentication guidance · LFCA domains and competencies updated2025-09-16; current page confirmed2026-09-30